Re: parse_str() patch
| From: | John Bafford | Date: | Mon, 11 Sep 2000 20:21:46 +0000 |
| Subject: | Re: parse_str() patch | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32957@lists.php.net to get a copy of this message | ||
But I need register_globals to be on for other stuff. The point of my
patch was so that I could process the string without polluting the local
variable space.
I will look into trying to create a patch based on the 4.0.3-dev version
that will fulfill my needs, unless you want to take a crack at that
instead.
-John
On Mon, 11 Sep 2000, Stanislav Malyshev wrote:
> JB>> The version of the patch in 4.0.3-dev puts variables into the local
> JB>> variable space even if the output array is passed into the function. If
> JB>> you use parse_str() and give it the output array, you don't need the
> JB>> variables to be set in the local space, and in some cases, this is even
> JB>> undesirable.
> JB>>
> JB>> Imagine: You are using parse_str() to evaluate a string with untrusted
> JB>> content. Someone could maliciously feed you a string that overwrites your
> JB>> variables with their content.
>
> Then you need to unset register_globals. Maybe I'll make some patch to do
> it, but what your patch did was really wrong (name[] didn't work and there
> were more problems with that).
>
> --
> Stanislav Malyshev stas@zend.com http://www.zend.com/
>
> +972-3-6139665 ext.106
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
--
John Bafford
dshadow@zort.net
http://www.dshadow.com/